Security
Security at Euler
Euler has undertaken one of the world's largest DeFi security programs, with millions invested across formal verification, independent review, audits, competitions, and related security work. The program covers protocol design, implementation, deployment, operation, monitoring, and incident response.
- Formal verification
- Euler V2 core and EulerEarn
- Security record
- More than 60 engagements

Verification and review
Formal methods, human review, and deployment verification target different failure modes across the protocol lifecycle.
Formal verification
Certora has formally verified properties of the Euler V2 core and EulerEarn, alongside manual review, fuzzing, and testing.
Review the verification recordIndependent security review
The public record covers more than 60 engagements across core contracts, oracles, periphery contracts, EulerEarn, EulerSwap, integrations, and application infrastructure.
View security reviewsDeployment verification
Security-relevant deployments are matched at the bytecode level to builds from exact source commits and compared with their most recent audited baselines.
View deployment reportsMonitoring and response
Platform-level monitoring targets critical, implementation-level threats to the protocol contracts and can lead to a factory pause of upgradeable vaults. Monitoring of individual vaults and markets — oracle behaviour, governance changes, liquidity, and positions — is the responsibility of their curators, risk managers, and integrators.
Monitoring, pause, and upgrade controlsBug bounty and Safe Harbor
Euler maintains a live Cantina bug bounty. An executed SEAL Safe Harbor agreement defines a separate path for qualifying emergency whitehat action during an active or imminent exploit.
Protocol security and market risk
Euler V2 is built from independent vaults rather than a single shared lending pool. Vaults select their collateral relationships, oracle routes, interest-rate models, caps, hooks, and governance.
A position therefore depends on both the reviewed protocol components and the live configuration of the vaults it uses. Review deployed addresses, collateral links, oracles, caps, LTVs, liquidity, governors, role holders, and pending governance actions.